CareSwaps
Home How It Works Pricing FAQ For Facilities Login Subscribe

Privacy Policy

Last Modified: July 20, 2026 · Jurisdiction: Colorado

1. Overview and Scope

CareSwaps, LLC (the “Company,” “we,” “us,” or “our”) respects your privacy and are committed to protecting it through our compliance with this Privacy Policy (this “Privacy Policy”).

This Privacy Policy describes the types of information we may collect from you or that you may provide when you access and use www.careswaps.com (“CareSwaps”) or www.patientswaps.com (“PatientSwaps”) (collectively, the “Websites”), including any products or services offered on or through the Websites (collectively referred to as the “Services”), whether as a guest or a registered user, and our practices for collecting, using, maintaining, protecting, and disclosing that information.

The Company operates two related web-based platforms:

  • CareSwaps (available at www.careswaps.com) - A family- and caregiver-facing platform that helps families explore senior-care transfer options through a subscription service.
  • PatientSwaps (available at www.patientswaps.com) - A facility-facing platform that provides algorithmic transfer matching technology to participating senior-care facilities.

This Privacy Policy applies to information we collect from CareSwaps and PatientSwaps users:

  • On the Websites and through the Services.
  • In email, text, and other electronic messages between you and the Company or the Websites.
  • Through mobile and desktop applications, if we make downloadable applications available from the Websites in the future, which provide dedicated non-browser-based interaction between you and the Websites.
  • When you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this Privacy Policy.

It does not apply to information collected by:

  • Us offline or through any other means, including on any other website operated by the Company or any third party.
  • Any third party, including through any application or content (including advertising) that may link to or be accessible from or through the Websites.

Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Websites or the Services. By accessing or using the Websites and the Services, you agree to this Privacy Policy. This Privacy Policy may change from time to time (see Changes to This Policy in Section 10 below). Your continued use of the Websites or the Services after we make changes is deemed to be acceptance of those changes, so please check the Privacy Policy periodically for updates.

2. Information We Collect and How We Collect It

We collect several types of information from and about users of our Websites and Services, including information:

  • By which you may be personally identified, such as name, postal address, email address, telephone number, or any other identifier by which you may be contacted online or offline (“personal information”);
  • That is about you but individually does not identify you; and/or
  • About the Services you use, your internet connection, the equipment you use to access our Websites, and usage details.

We collect this information:

  • Directly from you when you provide it to us.
  • Automatically as you navigate through the site. Information collected automatically may include usage details, IP addresses, and information collected through cookies, web beacons, and other tracking technologies.
  • From third parties, for example, our business partners.

2.1 Information You Provide to Us

The information we collect on or through our Websites and Services may include:

  • Information that you provide by filling in forms. This includes information provided at the time of registering to use our Websites, subscribing to our Services, posting material, or requesting further services. We may also ask you for information when you report a problem with our Websites or Services.
  • Records and copies of your correspondence (including email addresses), if you contact us.
  • Your responses to surveys that we might ask you to complete for research purposes.
  • Details of transactions you carry out through our Websites, including the nature of any Services ordered and your billing address. You may be required to provide financial information before placing an order through our Websites.
  • Your search queries on the Websites.
  • Information that you provide to us or authorize us to request from third parties (including, but not limited to, healthcare providers) on your behalf in furtherance of your use of the Services offered on or through the Websites. This includes general personal and demographic information, medical history, and other personal or protected health information.
  • Information that you provide when responding to text message or email correspondence from us, if you have opted-in to receiving such communications.

For CareSwaps users we may also collect:

  • Account and Contact Data: Name, email address, phone number, state of residence, relationship to the resident, and login credentials.
  • Subscription and Billing data: Billing name, billing address, and payment method. Credit card processing is handled by Stripe (we do not store full card numbers).
  • Intake Form Data: Information about your loved one or resident submitted through our intake forms, which may include name, date of birth, current living situation, care needs, power-of-attorney status, preferred timeline, payer information, and related details.
  • Dashboard and Document Uploads: Documents or information you upload to your CareSwaps account dashboard.
  • Communications: Emails, support inquiries, form submissions, and phone conversations with our team.

For PatientSwaps users we may also collect:

  • Facility Account Data: Facility name, location, license numbers, regulatory identifiers, and designated account contacts.
  • Staff and User Credentials: Individual user names, email addresses, job titles, login credentials, and multi-factor authentication information.
  • Facility Operational Data: Bed inventory, bed types, availability status, payer acceptance profiles, occupancy metrics, and network participation information.
  • Matching Query Data: Parameters submitted to the matching algorithm, which may include patient-level information as directed by the facility.
  • Communications: Messages, support inquiries, and correspondence between PatientSwaps users and the Company.

2.2 Automatically Collected Technical Data

As you navigate through and interact with our Websites and Services, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:

  • Details of your visits to our Websites, including traffic data, location data, logs, and other communication data and the resources that you access and use on the Websites.
  • Information about your computer and internet connection, including your IP address, operating system, and browser type.

The information we collect automatically may include personal information, or we may maintain it or associate it with personal information we collect in other ways or receive from third parties. It helps us to improve our Websites and to deliver a better and more personalized service, including by enabling us to:

  • Estimate our audience size and usage patterns.
  • Store information about your preferences, allowing us to customize our Websites and Services according to your individual interests.
  • Speed up your searches.
  • Recognize you when you return to our Websites.

The technologies we use for this automatic data collection may include, without limitation:

  • Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your computer. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting you may be unable to access certain parts of our Websites or Services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Websites. For information about managing your privacy and security settings for cookies, see Section 6 (below).
  • Web Beacons. Pages of our Websites and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).

Some content or applications, on the Websites are served by third parties, including content providers and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Websites. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services.

We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about targeted content, you should contact the responsible provider directly.

2.3 PHI and Health-Related Information

The Company is a healthcare technology platform. We are not a healthcare provider, and we are not a “Covered Entity” as defined by the Health Insurance Portability and Accountability Act (“HIPAA”). When the Company processes Protected Health Information (“PHI”) on behalf of a participating facility, we do so as a Business Associate under a Business Associate Agreement (“BAA”). In that context, HIPAA individual rights (such as the right to access, amend, or receive an accounting of disclosures of PHI) should generally be exercised through the applicable healthcare facility (the “Covered Entity”), not directly through the Company. If you wish to exercise a HIPAA right relating to PHI that we have processed on behalf of a facility, please contact the applicable facility directly.

Information submitted directly by patients, families, and caregivers through CareSwaps before any facility relationship exists (e.g., through an intake form) is protected under this Privacy Policy and applicable federal and state privacy and security laws. We apply HIPAA-compliant administrative, technical, and physical safeguards to this information as a matter of best practice. If and when that information is later shared with a facility under a BAA, it becomes subject to the BAA terms.

The Company will cooperate with facility requests to fulfill individual rights obligations as required by the applicable BAA. If a breach involves PHI that the Company processes on behalf of a facility, we will notify the applicable Covered Entity as required by the BAA and HIPAA (45 CFR § 164.410). The Covered Entity is responsible for providing notification to affected individuals, HHS, and (where applicable) the media, unless that obligation is expressly delegated to the Company under the BAA.

The Company may also have independent state-law breach notification obligations for personal information it holds directly (i.e., not under a BAA).

3. How We Use Your Information

We use information that we collect about you or that you provide to us, including any personal information:

  • To present our Websites and their contents to you.
  • To provide you with information, products, or services that you request from us.
  • To fulfill any other purpose for which you provide it.
  • To provide you with notices about your account, including expiration and renewal notices.
  • To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
  • To notify you about changes to our Websites or any products or services we offer or provide through them.
  • To allow you to participate in interactive features on our Websites.
  • To provide you with the Services offered on or through the Websites including to: (a) provide you with access to algorithmic bed-matching and transfer matching software services; (b) identify and display potential transfer opportunities based on operational factors (geographic proximity, bed availability, payer acceptance, and timing); (c) share de-identified operational signals and matching information with participating facilities as authorized and in accordance with the applicable Business Associate Agreement; and (d) maintain records regarding your use of the Platform, matching queries, and matching activity as required by applicable law.
  • In any other way we may describe when you provide the information.
  • For any other purpose with your consent.

We do not: (a) sell personal data or PHI; (b) use PHI for advertising, marketing, or targeted content; or (c) use health information to make or influence clinical decisions.

We may de-identify information in accordance with HIPAA (45 CFR § 164.514(b)) such that there is no reasonable basis to believe the information can identify an individual. Properly de-identified information is not PHI and is not subject to HIPAA restrictions.

The Company may use de-identified and aggregated information for lawful business purposes, including:

  • Platform analytics, performance monitoring, and service improvement
  • Network-level benchmarking and utilization insights
  • Algorithm optimization and feature development
  • Research and quality improvement initiatives
  • Industry reporting and thought leadership (in aggregate form only)

We will not attempt to re-identify de-identified information and will not use de-identified data to contact or identify specific individuals.

4. How We Share Your Information

We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.

We may disclose personal information that we collect or you provide as described in this Privacy Policy:

  • To our subsidiaries and affiliates.
  • To contractors, service providers, and other third parties we use to support our business.
  • To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of the Company’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by the Company about our Website users is among the assets transferred.
  • To payment processors (e.g., Stripe).
  • To a third-party involved in your care.
  • To fulfill the purpose for which you provide it.
  • For any other purpose disclosed by us when you provide the information.
  • With your consent.

We may also disclose your personal information:

  • To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
  • To enforce or apply our Terms and Conditions and other agreements, including for billing and collection purposes.
  • If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of the Company, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.

For CareSwaps users, when a family user affirmatively opts into the matching process, we may share relevant information with participating facilities as needed to facilitate transfer matching. PHI is shared only with facilities that have executed a BAA with the Company. De-identified operational signals (such as geographic demand information) may be shared more broadly to notify facilities of interest, but never in a form that identifies a specific patient or family.

For PatientSwaps users, transfer-related information may be shared between facilities as directed by the referring facility and as permitted under the applicable BAA.

5. Third-Party Service Providers and Data Architecture

We use third-party service providers to operate our platforms. Each provider that processes PHI has executed a BAA with the Company. Providers that receive only de-identified or non-PHI data are bound by data processing agreements and confidentiality obligations. We use operational controls to segregate PHI from systems that do not require access to it. PHI is permitted only in systems covered by a BAA. Systems without a BAA receive only de-identified identifiers, operational data, or public business information, as currently designed. The Company periodically reviews its service provider arrangements to confirm compliance with these requirements.

We maintain a current list of service providers with PHI access. You may request this list any time by contacting privacy@careswaps.com.

6. Cookies, Analytics, and Tracking

6.1 Types of Cookies

The Company uses a minimal set of cookies and similar technologies on the Websites to:

  • Maintain user login sessions and authentication
  • Remember user preferences and settings
  • Track usage patterns and improve platform performance
  • Detect and prevent fraud or unauthorized access.

These cookies include:

  • Essential Cookies: Required for platform login and basic functionality (session management, CSRF protection)
  • Analytics Cookies: Used on public marketing pages only to track page views and feature usage to improve platform experience (Google Analytics, with IP anonymization). Analytics cookies are not used on authenticated dashboards or pages that handle PHI.
  • Security Cookies: Detect suspicious activity and prevent unauthorized access

6.2 What we do not use

  • No cross-site advertising or retargeting cookies
  • No third-party marketing pixels
  • No social media tracking widgets
  • No fingerprinting or persistent tracking technologies beyond the cookies described above

6.3 Managing cookies

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. Disabling essential cookies may prevent you from using platform features that require authentication.

7. Your Privacy Choices and Rights

7.1 General rights (all users)

Depending on your jurisdiction and our relationship with you, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate personal data.
  • Delete personal data we have collected, subject to legal retention obligations.
  • Obtain a portable copy of your personal data in a commonly used format.
  • Opt-out of targeted advertising, sale of personal data, or profiling that produces legal or similarly significant effects.

To exercise any of these rights, contact privacy@careswaps.com. We will respond within 45 days (or such shorter period as applicable law requires).

7.2 Colorado Privacy Act (CPA) rights

Colorado residents may have additional rights under the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) if the Company meets the applicable processing thresholds, including:

  • Right to Know: What personal information is collected and how it is used
  • Right to Access: Obtain a copy of personal information
  • Right to Deletion: Request deletion, except where legally required to retain
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out: Opt out of "sale" or "sharing" of personal information

The Company does not sell personal data and does not engage in targeted advertising. If these practices change, we will update this Privacy Policy and provide opt-out mechanisms as required by the Colorado Privacy Act.

7.3 Additional State Privacy Rights

Residents of other states with comprehensive consumer privacy laws (such as California, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, and Virginia) may have similar rights under their respective statutes, including the rights to:

  • Confirm whether we process their personal information.
  • Access and delete certain personal information.
  • Correct inaccuracies in their personal information, taking into account the information’s nature and processing purpose.
  • Data portability.
  • Opt-out of personal data processing for: (i) targeted advertising (excluding Iowa); sales; or profiling in furtherance of decisions that produce legal or similarly significant effects (excluding Iowa and Utah).
  • Either limit (opt-out of) or require consent to process sensitive personal data.

The exact scope of these rights may vary by state. To exercise any of these rights please send an email to: privacy@careswaps.com.

7.4 HIPAA rights (PHI under a BAA)

If your request relates to PHI that the Company processes on behalf of a healthcare facility under a BAA, HIPAA individual rights (including access, amendment, and accounting of disclosures) should be exercised through the applicable Covered Entity (the facility). Please contact the facility directly to exercise these rights. The Company will cooperate with the facility as required by the BAA.

7.5 Right to Appeal

If we deny a privacy rights request, we will explain the basis for the denial and you may appeal by responding to our denial communication. If we deny your appeal, you may file a complaint with the Colorado Attorney General (coag.gov) or, for PHI matters involving a Covered Entity, with the U.S. Department of Health and Human Services Office for Civil Rights (hhs.gov/ocr).

8. Data Security and Retention

8.1 Security Safeguards

We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. The Company maintains administrative, physical, and technical safeguards designed to protect personal information and PHI, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access controls (RBAC) limiting data access to authorized personnel with a documented business need
  • Multi-factor authentication (MFA) for administrative accounts
  • Audit logging of access to PHI and sensitive systems
  • Periodic security risk assessments
  • Workforce training on privacy and security obligations

PatientSwaps users may request integration with their existing Electronic Health Records (EHR) or healthcare information systems. The Company may support such integrations in the future and, if offered, will execute appropriate data sharing agreements with the facility’s vendor.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Websites or Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although we implement measures designed to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Websites. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Websites, except to the extent such circumvention results from our failure to maintain reasonable safeguards.

8.2 Data Retention

We retain information only as reasonably necessary to provide our services and comply with legal obligations:

  • HIPAA Security Rule documentation: Retained for a minimum of six (6) years as required by 45 CFR § 164.530(j). This applies to policies, procedures, and compliance records — not to all PHI.
  • PHI processed under a BAA: Retained as specified in the applicable BAA and as required by law, then securely destroyed.
  • Account and subscription data: Retained for the duration of the account relationship and a reasonable period thereafter for billing, legal, and audit purposes.
  • Tax and financial records: Retained for seven (7) years.
  • De-identified data: May be retained indefinitely for analytics, benchmarking, and platform improvement.

When retention is no longer required, data is securely deleted or de-identified in accordance with applicable standards.

8.3 Breach

In the event of a security breach that results in the unauthorized access, acquisition, or disclosure of personal information, we will investigate the incident and take appropriate steps to mitigate any harm. Where required by applicable state or federal law (including, without limitation, breach notification requirements under Colorado law and any other state in which we operate) we will notify affected individuals and, where required, the appropriate state or federal authorities, in the manner and within the timeframes prescribed by law. Such notification will include, to the extent known, a description of the incident, the types of personal information involved, and the steps individuals may take to protect themselves. We maintain and regularly review our information security practices to minimize the risk of unauthorized access to personal information, and we will continue to update our security measures as necessary to address evolving threats.

9. Children’s Privacy

The Services are designed for adult users (e.g., family members, caregivers, and healthcare facility staff arranging senior-care transfers). Our Services are not directed to children under 13, and we do not knowingly collect personal data from children.

Family and caregiver users may provide information about a loved one or resident as part of the intake and matching process. By submitting such information, you represent that you have the authority to do so on behalf of that individual (for example, as a legal guardian, power of attorney, or authorized family member).

If we become aware that any user has provided information through the Websites about a child, we will delete that information promptly. If you believe a child under 13 has submitted information to us, please contact privacy@careswaps.com and we will promptly delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal obligations. When we make material changes, we will:

  • Post the updated policy with a new effective date on the Websites
  • Where required by law or contract, provide advance notice to active subscribers by email.

Continued use of CareSwaps or PatientSwaps after the effective date of an updated policy constitutes acceptance of the updated terms. We encourage you to review this policy periodically.

11. Contact Information

For privacy questions, rights requests, or to report a concern, contact us:

  • Privacy Contact: Michael Ford
  • Email: privacy@careswaps.com
  • Phone: (970) 306-7131
  • Mail: CareSwaps, LLC, 2519 S. Shields St., Suite 1K PMB 1159, Fort Collins, CO 80526

For regulatory complaints contact:

  • HHS Office for Civil Rights — hhs.gov/ocr (PHI)
  • Colorado Attorney General — coag.gov (CPA).

CareSwaps

Healthcare technology platform enabling families to find senior care facility transfer opportunities — across skilled nursing, assisted living, memory care, and more — through algorithmic matching and swap chain technology.

hello@careswaps.com

Fort Collins, Colorado

Platform

How It Works Pricing FAQ Subscribe — $299/mo

Legal

Terms of Service Privacy Policy About Our HIPAA Role Data Retention Cancel Subscription For Facilities →

© 2026 CareSwaps, LLC. Healthcare technology platform. All rights reserved. CareSwaps does not provide medical care, clinical recommendations, or transportation services.

Accessibility: CareSwaps is committed to ensuring digital accessibility for people with disabilities. If you experience difficulty accessing any content on this site, please contact us at hello@careswaps.com or (970) 306-7131.

This site uses analytics cookies (Google Analytics) to understand how visitors use our platform. No health information is collected through cookies. See our Privacy Policy for details.